Last updated 9 October 2026
Privacy policy
AeroFlux at aeroflux.andnet.se fetches your data from Polar and shows it to you. We collect as little as possible, use it only to make the service work, and never sell or share anything for advertising. Here we explain how we process your personal data under the EU General Data Protection Regulation (GDPR) and Swedish law.
1. Data controller
The data controller is 23nisand, who runs the service as a private individual. Contact: info@andnet.se.
2. What data we process
- Account: name, username, password as a one-way hash (bcrypt – we can never see your password), email address if you provide one, chosen language, when the account was created and when you last used it.
- Linked accounts: your Polar user ID and an access key (token) that lets us fetch your data from Polar. If you use Discord: your Discord ID and, when you sign up, your display name and – if it is verified – your email address. We do not store your avatar, servers or messages.
- Health data from Polar (special category data under Art. 9 GDPR): workouts (sport, time, heart rate, heart rate zones, calories, distance, elevation, GPS route, training load and which watch was used), daily activity and steps, sleep, overnight recovery, heart rate throughout the day, cardio load and other measurements your Polar account shares, for example body measurements and skin temperature.
- Consent: which version of this policy you consented to and when.
- The leaderboard (optional): that you take part. Other participants then see your name, your steps, kilometres and streaks – nothing else.
- Invitations: if you were invited: when the invitation was created and used, and a short note written by the administrator.
- Security: when someone requests "Forgot password", the IP address is stored for 15 minutes to stop abuse. Reset links are stored only as a hash and are valid for one hour.
- Logs: the sync log contains your account number, the time and how many records were fetched – no health data. The web host logs IP address, time and which page was visited.
We use no analytics tools, ad networks, social media buttons or external fonts. The pages load nothing from third parties – except the map, and only when you choose to show it (see section 5).
3. Purposes and legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Create and manage your account, let you log in | Account, linked accounts | Contract, Art. 6(1)(b) |
| Fetch, store and show your training and health to you | Health data, Polar token | Your explicit consent, Art. 6(1)(a) and 9(2)(a) |
| The leaderboard, if you join | Name, steps, kilometres, streak | Your explicit consent, Art. 6(1)(a) and 9(2)(a) |
| Send a link when you forget your password | Name, email | Contract, Art. 6(1)(b) |
| Be able to show that consent was given | Consent | Legal obligation, Art. 6(1)(c) and 7(1) |
| Protect the service against intrusion and abuse | Security, logs | Legitimate interest, Art. 6(1)(f) |
Our legitimate interest is keeping the service and your data secure. The data is minimal and deleted quickly, so we consider that this interest outweighs the impact on your privacy. You can object to it (Art. 21).
Without consent to the health data the service cannot show anything, so consent is required to use it. You can withdraw your consent at any time under Account – all fetched Polar data is then deleted and the connection to Polar is removed. Processing before the withdrawal is not affected.
4. How long we keep data
- Account and health data: for as long as you use the account, so that you can follow your progress over a long time. We do not delete old history in an account that is in use. Everything is deleted when you delete the account, and the health data when you withdraw your consent.
- Accounts that are not used: if you have not used the account for 24 months, it is deleted automatically with all its data. If you have provided an email address, you first get a reminder 30 and 7 days before – logging in once is enough to keep the account.
- Empty accounts: accounts that are not connected to Polar and have no data are deleted after 30 days without use.
- Invitations: at most 90 days, and immediately if the account is deleted.
- IP addresses from "Forgot password": 15 minutes. Reset links: one hour.
- The sync log: the latest 3,000 lines (a few weeks), after which it is overwritten.
- The web host’s logs: until the end of the current month, then archived for at most one more month before being deleted automatically.
- The web host may take backups of the server so that it can be restored after a failure. They are overwritten automatically, so deleted data disappears from them too shortly afterwards.
5. Who receives the data
- Andnet Hosting (web hosting and email, servers in Sweden) processes the data on our behalf as a data processor under Art. 28 GDPR.
- Polar Electro Oy (Finland) is the source of your data. Polar is an independent controller for what you store with Polar, under Polar’s own privacy policy. We only fetch data you have approved at Polar, and when you disconnect Polar or delete your account we deregister the service at Polar so that it cannot fetch any more.
- Discord Inc. (USA) – only if you choose to log in with Discord. You are then sent to Discord’s website, and Discord is an independent controller for its own processing. We send no data to Discord.
- OpenStreetMap Foundation (United Kingdom, which has an EU adequacy decision) – only when you click "Show map" on a workout. The map images are then fetched from OpenStreetMap, which sees your IP address and which area the map shows.
- Other users only see your leaderboard figures, and only if you have joined the leaderboard.
- The administrator has technical access to the server but does not look at your health data. The admin page only shows name, login methods, whether Polar is connected, the latest sync and the number of days with data.
We never sell data and do not transfer it to countries outside the EU/EEA, except what you choose yourself (Discord) and the map above. We may be required to disclose data to authorities where the law requires it.
6. Your rights
Under the GDPR you have the right to
- access and data portability (Art. 15 and 20) – download all your data as JSON under Account,
- rectification (Art. 16) – change your name, username and email under Account. Health data is corrected in Polar; the next sync fetches the change,
- erasure (Art. 17) – delete your account and all data directly under Account,
- withdraw consent (Art. 7(3)) – under Account, as easily as you gave it,
- restriction of processing (Art. 18) and to object to processing based on legitimate interest (Art. 21).
Contact info@andnet.se if you want to exercise a right you cannot handle yourself in the service. We respond without undue delay and at the latest within one month. Charts, insights and summaries are calculated only for you. We make no automated decisions with legal or similarly significant effects for you (Art. 22).
7. Security
All traffic is encrypted with HTTPS. Passwords are hashed with bcrypt. The databases are stored outside the public web directory, each user has their own database, forms are protected against CSRF and password guessing is slowed down. If a personal data breach were to occur, we would report it to the Swedish Authority for Privacy Protection (IMY) within 72 hours, and inform you if it is likely to result in a high risk to you.
8. Age
You must be at least 13 years old to create an account. If you are under 18, we recommend reading this policy together with a parent or guardian.
9. Cookies and browser storage
We only use what is necessary for the service to work (Chapter 9, Section 28 of the Swedish Electronic Communications Act). That is why no cookie banner is needed.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
polar_sess | Cookie | Keeps you logged in and protects forms (CSRF) | 30 days, or until you log out |
aeroflux_lang | Cookie | Remembers whether you chose Swedish or English | 1 year |
polar-days, polar-metric, polar-lb, polar-route | Local storage | Remembers the chosen period and view | Until you clear your browser |
polar-map | Local storage | Remembers whether you chose to always show maps | Until you clear your browser |
Local storage stays in your browser and is never sent to us.
10. Complaints
If you are unhappy with how we process your data, you can lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se, Box 8114, 104 20 Stockholm, Sweden, or with the supervisory authority in the EU country where you live. Feel free to contact us first and we will try to resolve it.
11. Changes
If we change the policy in a way that affects you, you will be asked to approve the new version the next time you log in. The date at the top shows when it was last changed.
This policy is also available in Swedish. If the versions differ, the Swedish version applies.